DAUBNER, Lukáš and Adam POVAŽANEC. Data Loss Prevention Solution for Linux Endpoint Devices. Online. In ARES '23: Proceedings of the 18th International Conference on Availability, Reliability and Security. United States: Association for Computing Machinery, 2023, p. 1-10. ISBN 979-8-4007-0772-8. Available from: https://dx.doi.org/10.1145/3600160.3605036.
Other formats:   BibTeX LaTeX RIS
Basic information
Original name Data Loss Prevention Solution for Linux Endpoint Devices
Authors DAUBNER, Lukáš (203 Czech Republic, guarantor, belonging to the institution) and Adam POVAŽANEC (703 Slovakia, belonging to the institution).
Edition United States, ARES '23: Proceedings of the 18th International Conference on Availability, Reliability and Security, p. 1-10, 10 pp. 2023.
Publisher Association for Computing Machinery
Other information
Original language English
Type of outcome Proceedings paper
Field of Study 10200 1.2 Computer and information sciences
Country of publisher United States of America
Confidentiality degree is not subject to a state or trade secret
Publication form electronic version available online
WWW URL
RIV identification code RIV/00216224:14330/23:00131647
Organization unit Faculty of Informatics
ISBN 979-8-4007-0772-8
Doi http://dx.doi.org/10.1145/3600160.3605036
UT WoS 001122662500126
Keywords in English Data Loss Prevention; Auditing; Kernel Hooking; DLP; Data Leakage
Tags International impact, Reviewed
Changed by Changed by: RNDr. Pavel Šmerk, Ph.D., učo 3880. Changed: 7/4/2024 23:23.
Abstract
Endpoint data loss prevention (DLP) software monitors and protects data on the endpoint against accidental and malicious leakage. While the risk of such leakage is widely present in current systems, it is more so within the intelligent infrastructures due to potential impact, heterogeneity, and complexity. However, there is a significant gap in open solutions for wide Linux-based endpoints. Therefore, this paper discusses possible approaches towards Linux endpoint DLP solution, which would be widely available on Linux distributions, not relying on fragile assumptions and not undermining security controls. Namely, the focus is on audit and control of file system operations and external USB devices. The viable approaches are discussed, and a prototype solution is implemented using the ftrace framework for file system operations and combining the udev subsystem and the sysfs virtual file system for external USB devices. While the solution is demonstrated in scenarios involving various DLP channels, it also established a platform for further research based on the data from intercepted events.
Links
MUNI/A/1389/2022, interní kód MUName: Aplikovaný výzkum na FI: Bezpečnost počítačových systémů, softwarových architektur kritických infrastruktur s forenzními aspekty, zpracování dat pokročilých sensorů a algoritmy plánování v dopravě a logistice
Investor: Masaryk University
MUNI/G/1142/2022, interní kód MUName: Forensic Support for Building Trust in Smart Software Ecosystems
Investor: Masaryk University, Forensic Support for Building Trust in Smart Software Ecosystems, INTERDISCIPLINARY - Interdisciplinary research projects
PrintDisplayed: 25/8/2024 04:00